Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.5 CVE-2023-38220 Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Impro… Commerce Mitigation only Fix from $1,9502023-10-13 HIGH 8.8 CVE-2023-41841 An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile t… Fortios after 7.2.4 Fix from $1,9502023-10-10 HIGH 8.6 CVE-2023-3037 Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the p… Helpdezk Mitigation only Fix from $1,9502023-10-04 CRITICAL 9.1 CVE-2023-20186 A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an aut… iOS Mitigation only Fix from $2,3002023-09-27 HIGH 7.8 CVE-2023-44123 The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary … Android Mitigation only Fix from $1,9502023-09-27 HIGH 7.8 CVE-2023-44125 The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbit… Android Mitigation only Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-28055 Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network… Networker 19.7.0.5 / 19.8.0.3+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-0456 A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul… Apicast 2.12.2 / 2.13.2+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2022-47553 Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisati… Ekorrci Firmware Mitigation only Fix from $1,9502023-09-19 HIGH 7.5 CVE-2023-0813 A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic… Network Observability Mitigation only Fix from $1,9502023-09-15 HIGH 7.5 CVE-2023-28584 Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). Aqt1000 Firmware Patch available Fix from $1,9502023-09-05 HIGH 7.5 CVE-2023-33019 Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. 9206 Lte Firmware Patch available Fix from $1,9502023-09-05 HIGH 7.5 CVE-2023-33020 Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. 9206 Lte Firmware Patch available Fix from $1,9502023-09-05 MEDIUM 6.5 CVE-2023-32678 Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private… Zulip Server 7.3+ Fix from $1,6002023-08-25 HIGH 7.8 CVE-2023-3899 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red… Subscription Manager 1.28.39 / 1.29.37+ Fix from $1,9502023-08-23 CRITICAL 9.1 CVE-2023-39402 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 CRITICAL 9.1 CVE-2023-39403 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 CRITICAL 9.1 CVE-2023-39399 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 CRITICAL 9.1 CVE-2023-39400 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 CRITICAL 9.1 CVE-2023-39401 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 CRITICAL 9.1 CVE-2023-39398 Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and wri… Emui Mitigation only Fix from $2,3002023-08-13 MEDIUM 6.7 CVE-2023-28385 Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable es… Next Unit Of Computing Firmware 2.0.0.9+ Fix from $1,6002023-08-11 HIGH 8.8 CVE-2023-4243 The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, … Full Customer after 2.2.3 Fix from $1,9502023-08-09 MEDIUM 6.5 CVE-2023-36826 Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can do… Sentry 23.5.2+ Fix from $1,6002023-07-25 MEDIUM 5.4 CVE-2023-23568 Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This iss… Command Centre 8.50.2831 / 8.60.2347+ Fix from $1,6002023-07-25 MEDIUM 5.4 CVE-2023-25074 Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue … Command Centre 8.50.2831 / 8.60.2347+ Fix from $1,6002023-07-25 MEDIUM 6.5 CVE-2023-22428 Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre:… Command Centre 8.50.2831 / 8.60.2347+ Fix from $1,6002023-07-24 CRITICAL 9.8 CVE-2023-3805 A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712. This iss… Video Surveillance Management System after 2023-07-12 Fix from $2,3002023-07-21 MEDIUM 6.5 CVE-2023-3574 Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1. Customer Management Framework 3.4.1+ Fix from $1,6002023-07-10 HIGH 7.1 CVE-2023-25517 NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which i… Gpu Display Driver 11.13 / 13.8+ Fix from $1,9502023-07-04